CVE-2026-55771 HIGH

CVE-2026-55771: CedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Vendor Cedar-Policy
Product cedar-java
Weakness CWE-94 · Code injection
Published July 13, 2026
Last update July 13, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted null/self branches which could lead to incorrect equality comparisons. The EntityIdentifier.equals() method has inverted logic for null and self-reference checks, returning true for null comparisons and false for self-comparisons. This does not affect Cedar authorization decisions (computed in Rust from JSON), but could affect integrators who perform their own equality checks on entity identifiers. This issue has been fixed in version 4.9.0.

Key dates

02Disclosure timeline

July 13, 2026 CVE published

Related vulnerabilities

04Related CVE